QID 91845

Date Published: 2021-12-15

QID 91845: Microsoft Windows Codecs Library HEVC Video And Web Media Extensions Remote Code Execution (RCE) Vulnerability for December 2021

A remote code execution vulnerability exists in the way that Microsoft Windows Codecs Library handles objects in memory.

Affected Product:
"HEVC from Device Manufacturer" media codec before version 1.0.42702.0
"WEB from Device Manufacturer" media codec before version 1.0.42192.0

QID detection Logic:
The gets the version of HEVCVideoExtension and WebMediaExtensions by querying wmi class Win32_InstalledStoreProgram.

An attacker who successfully exploited this vulnerability can compromise confidentiality, integrity and availability of the system

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Users are advised to check CVE-2021-41360 CVE-2021-40452 CVE-2021-40453 and CVE-2021-43214 for more information.

    CVEs related to QID 91845

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-40452 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40452
    CVE-2021-40453 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2021-40453
    CVE-2021-41360 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2021-41360
    CVE-2021-43214 URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2021-43214